bodminman Posted February 18, 2015 Posted February 18, 2015 http://news.sky.com/story/1429549/jamie-olivers-website-compromised-by-hackers 1
ITGuyWestMidlands Posted February 18, 2015 Posted February 18, 2015 Ms scep has been alerting us to this for weeks. Our food tech kids have been visiting it daily. Thought it was a false positive so ignored it....
elsiegee40 Posted February 18, 2015 Posted February 18, 2015 Daughter uses this site a lot and had no apparent problems. I saw this earlier today and am currently guiding her through throwing the anti malware toolset at her laptop. Fortunately Java was up to date with no old versions, but we are doing a clean install to be on the safe side.
jamesfed Posted February 18, 2015 Posted February 18, 2015 @ITGuyWestMidlands same here! Seen a good few notices popup in our malware mailbox about it (linked to SCEP); oh well now I know!
Sylv3r Posted February 18, 2015 Posted February 18, 2015 Our SCCM Forefront has been picking up on this for for at least 6 weeks - as a post above I thought it was a false positive so just ignored it. I'm surprised it's taken that long for them to pick it up.
ITGuyWestMidlands Posted February 18, 2015 Posted February 18, 2015 And people knock it. We also run sophos and that didnt pick it up...
jamesfed Posted February 18, 2015 Posted February 18, 2015 And people knock it. We also run sophos and that didnt pick it up... Its free (kinda), darn simple (well once you have a SCCM server running) and 'just works' keeps me happy! 1
Arthur Posted February 18, 2015 Posted February 18, 2015 (edited) Since Sky News can't be bothered to link to the MalwareBytes blog post they refer to, here it is... https://blog.malwarebytes.org/exploits-2/2015/02/celebrity-chef-jamie-olivers-website-hacked-redirects-to-exploit-kit http://a.pomf.se/whkmnl.png http://a.pomf.se/yoelwh.png Edited February 18, 2015 by Arthur 2
jamesfed Posted February 18, 2015 Posted February 18, 2015 Just thinking about it shouldn't Smoothwall pickup on these kinds of things like they did with that BBC website weirdness a year or so ago?
Arthur Posted February 18, 2015 Posted February 18, 2015 (edited) shouldn't Smoothwall pickup on these kinds of things You would have thought so, but VIPRE anti-virus is pretty rubbish in terms of protection according to AV-Test (worse than AVG!). I suppose you could block all .xyz domains, octet-streams for staff and students and install/configure EMET. Edit. According to the blog post above... The Exploit Kit launched at least three exploits (Flash (CVE-2015-0311), Silverlight (CVE-2013-0074) and Java) which were successfully blocked by Malwarebytes Anti-Exploit. The exploit was stopped at Layer 1 (ROP gadget) as it was calling the VirtualAlloc API. http://a.pomf.se/oiywjd.png I think EMET would definitely help in this case (assuming your plugins weren't up-to-date). Edited February 18, 2015 by Arthur
ZeroHour Posted February 19, 2015 Posted February 19, 2015 Does anyone have a screenshot of their first detection of the problem? (either email or av console)
JRowley Posted February 19, 2015 Posted February 19, 2015 (edited) Does anyone have a screenshot of their first detection of the problem? (either email or av console) I don't have the first one as we just delete our notifications after a month, here is the oldest notification we have: Configuration Manager Endpoint Protection has detected malware on one or more computers in your organization Collection name: - Malware Name: Exploit:JS/Fiexp.C Number of infections: 1 Last detection time(UTC time): 1/22/2015 10:31:33 AM These are the infections of this malware: 1. Computer name: - Domain: - Detection time(UTC time): 1/22/2015 10:31:33 AM Malware file path: webscript:_http://www.jamieoliver.com/news-and-features/features/flavoured-breads/#tkwjEuwgVG0fxkZh.97 Remediation action: Remove Action status: Succeeded To view further information about malware activity in your organization, run Malware Details Report. Note: No additional Malware Detection alerts will be generated for these computers if no new infections are found in the next 24 hours. Edit: Turns out this is the earliest one, I thought I had seen one before this but doesn't look like it. Edited February 19, 2015 by JRowley 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now